Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2700

Опубликовано: 15 мая 2023
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.

A vulnerability was found in libvirt. This security flaw occurs due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libvirtOut of support scope
Red Hat Enterprise Linux 7libvirtOut of support scope
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt:av/libvirtWill not fix
Red Hat Enterprise Linux 8 Advanced Virtualizationvirt-devel:av/libvirtWill not fix
Red Hat Enterprise Linux 8virt-develFixedRHSA-2023:382227.06.2023
Red Hat Enterprise Linux 8virtFixedRHSA-2023:382227.06.2023
Red Hat Enterprise Linux 8.6 Extended Update Supportvirt-develFixedRHSA-2023:479929.08.2023
Red Hat Enterprise Linux 8.6 Extended Update SupportvirtFixedRHSA-2023:479929.08.2023
Red Hat Enterprise Linux 9libvirtFixedRHSA-2023:371521.06.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2203653libvirt: Memory leak in virPCIVirtualFunctionList cleanup

EPSS

Процентиль: 7%
0.0003
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.

CVSS3: 5.5
nvd
около 2 лет назад

A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.

CVSS3: 5.5
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 5.5
debian
около 2 лет назад

A vulnerability was found in libvirt. This security flaw ouccers due t ...

suse-cvrf
почти 2 года назад

Security update for libvirt

EPSS

Процентиль: 7%
0.0003
Низкий

6.3 Medium

CVSS3